mirror of
https://github.com/react/react-native-devtools-frontend.git
synced 2026-09-28 13:13:37 +08:00
This change addresses 2 issues in uglify-js and socket.io-parser. See reports below for details: - https://www.mend.io/vulnerability-database/CVE-2022-37598 - https://nvd.nist.gov/vuln/detail/CVE-2022-2421 The socket.io-parser issue was addressed by running npm audit via the following command: `npm run install-deps audit fix --audit-level=critical` Since audit didn't recognize the uglify-js issue, I updated uglify-js to version 3.13.10 "manually" by adding an entry in manage_node_deps.py. running install-deps to update package-lock.json and then removing the entry from manage_node_deps.py. Bug: None Change-Id: I29238b14773a1b94b973886b0bb700f50e45cfa9 Reviewed-on: https://chromium-review.googlesource.com/c/devtools/devtools-frontend/+/4061168 Reviewed-by: Benedikt Meurer <bmeurer@chromium.org> Commit-Queue: Brandon Walderman <brwalder@microsoft.com>